Approval
Approve connectors for the workspace or specific teams, and govern which tools each team and role can use.
Connector access is governed in two layers: approving a connector for a team or the whole org, and controlling which tools within it are allowed.
Approve connectors
Org admins (or holders of tools:manage) manage approvals at
Settings → Connectors.
- Marketplace — connectors not yet approved. Approve one for:
- Org-wide — available to every team.
- Specific teams — installed for the teams you choose.
- Approved MCPs — connectors already assigned, with the teams (or org-wide) they're assigned to. You can change scope or revoke here.
- Requests — when a member requests a connector, it appears here to approve or reject.
Approving a connector installs it for the chosen scope and seeds its tool catalog.
Govern tool access
Approving a connector doesn't have to mean allowing every tool inside it. On a team's connector page, set the tool-access policy:
- Mode
all_tools— every tool is allowed unless explicitly denied.selected_tools— only explicitly allowed tools are usable.
- Rules — allow or deny specific tools, scoped to a team role (
memberorteam_admin) or an individual user.
This lets you, for example, allow a team to read CRM records while blocking tools that write or change admin settings.
Why this matters
MCP tools can read data, write records, trigger actions, or reach sensitive systems. Scoping access by connector, tool, role, and user keeps agent capabilities aligned with policy.
Who can do what
| Action | Required access |
|---|---|
| Approve / revoke connectors | Org admin or tools:manage. |
| Configure a connector's credentials | tools:manage or team admin. |
| Set a team's tool-access policy | tools:manage or team admin. |
| Request a connector | Any team member. |